The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.8. This is due to the plugin not properly verifying a user's identity prior to logging them in as that user. This makes it possible for unauthenticated attackers to authenticate as any user as long as they have configured OTP login by phone number.
History

Wed, 12 Feb 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jan 2025 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Scriptsbundle
Scriptsbundle adforest
Weaknesses CWE-306
CPEs cpe:2.3:a:scriptsbundle:adforest:*:*:*:*:*:wordpress:*:*
Vendors & Products Scriptsbundle
Scriptsbundle adforest

Wed, 22 Jan 2025 07:15:00 +0000

Type Values Removed Values Added
Description The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.8. This is due to the plugin not properly verifying a user's identity prior to logging them in as that user. This makes it possible for unauthenticated attackers to authenticate as any user as long as they have configured OTP login by phone number.
Title AdForest <= 5.1.8 - Authentication Bypass
Weaknesses CWE-288
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2025-02-12T19:14:31.820Z

Reserved: 2024-12-20T16:29:31.692Z

Link: CVE-2024-12857

cve-icon Vulnrichment

Updated: 2025-02-12T19:14:07.312Z

cve-icon NVD

Status : Analyzed

Published: 2025-01-22T07:15:16.237

Modified: 2025-01-24T19:18:01.417

Link: CVE-2024-12857

cve-icon Redhat

No data.